Consumer protection: identity theft; identity theft protection act; modify. Amends ses. 3, 12 & 12b of 2004 PA 452 (MCL 445.63 et seq.); adds secs. 11a, 11b, 20, 20a, 20b & 20c & repeals secs. 15 & 17 of 2004 PA 452 (MCL 445.75 & 445.77).
What changed between versions
Added new definitions for 'medical records or information' (including mental health histories and x-rays), 'local registrar,' and 'redact' (specifying exactly how many digits of SSNs or driver license numbers can be exposed).
Created new Section 11a requiring owners of personal information to implement and maintain reasonable security procedures, including appointing a security coordinator and adhering to the NIST Cybersecurity Framework 2.0.
Created new Section 11b mandating a specific, good-faith investigation process when a security breach is suspected, including assessing scope and identifying affected individuals.
Modified Section 12 to clarify notice requirements, specifying that if a breach affects 100 or more residents, the Attorney General must also be notified, and outlining specific methods for providing notice (written, electronic, or telephone).
Added new Sections 20a, 20b, and 20c granting the Attorney General new powers to issue written demands for documents and testimony, and establishing civil fines up to $25,000 for non-compliance with these demands or for failing to implement security measures.
Removed the original effective date of July 2, 2006, and replaced it with a new effective date of June 5, 2025, indicating this is a major revision of the existing law.